Jump to content

PCI Compliance


Recommended Posts

Hi There,

 

Just got a newsletter from Protx informing me of changes. It looks like all VPS Direct merchants will need to undergo a PCI Compliance Audit. The majority of this audit involves WHMCS.

 

Just wanted to know if you guys at WHMCS have already taken this into consideration?

 

Thanks

Link to comment
Share on other sites

PCI Compliance isnt just to do with the billing system.

 

Some basics you need to have

 

ssl cert for billing system login and order

IDS - Intrusion Detection System

Firewall Dedicated if possible.

WHMCS Database on a seperate server - protected by IPTables or a good firewall

Regular Security Audits

One2One staff training & Updates

Link to comment
Share on other sites

Isnt' this different from country to country? I also got a notice about this recently from our bank, and we're told that our billing system, and client DB needs to be on our own dedicated server, in a locked cage. So, this is a problem for VPS type clients. Does anyone know anything about this? Is our banks too paranoid?

Link to comment
Share on other sites

PCI Compliance isn't that hard to achieve to be honest - we had the same notification from Protx and had compliance in under a week. This obviously does depend on your own sitiation, however our servers were already pretty well up to stratch against the vulnerability testing. You will have issues though if you're using shared hosting where you cannot make the server changes to comply with their requirements.

Link to comment
Share on other sites

We had nothing specified about what could be run on the server. Basically, you have to complete a checklist to ensure that you and your staff know how to handle client data correctly, then complete the vulnerability assessment. We used http://www.scanalert.com/, and if you read the bottom of this page it's free ;)https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/merchant/PCICompliance-outside

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated